logoalt Hacker News

strcatyesterday at 9:02 PM0 repliesview on HN

No, that's a misconception. GrapheneOS has only ever supported devices where the cellular radio is isolated from the OS and unprivileged. It does not have access to memory it hasn't been permitted to access by GrapheneOS. Wi-Fi, Bluetooth, NFC, UWB, etc. are isolated components too. Our hardware requirements are listed in our FAQ and require proper isolation for radios:

https://grapheneos.org/faq#future-devices

8th, 9th and 10th gen Pixels provide our full set of requirements with 7 years of support from launch. 6th and 7th gen Pixels are missing the ARMv9 security features including the extremely important hardware memory tagging (MTE) feature we heavily use to protect against exploitation. Even the first devices we supported back in 2014 including the Nexus 5 had isolation for the cellular radio but similar isolation for Wi-Fi/Bluetooth started with the Nexus 5X.